Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Blackbeltstudio Most Popular Ringtones9/9/201417/6/2026
The Most Popular Ringtones (aka com.bbs.mostpopularringtones) application 32 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.1)1.2%—Blackberry OSBlackberry Q10Blackberry Q5Blackberry Z10+118/8/201417/6/2026
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in…
ModificadaMedia (4.9)0.38%—Blackberry Enterprise ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express18/8/201417/6/2026
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
ModificadaMedia (6.8)0.61%—Carbonblack Carbon Black22/4/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to api/user.
ModificadaAlta (9.3)5.7%—Blackberry OSBlackberry Z1012/4/201417/6/2026
Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode has been previously enabled, allows remote attackers to execute arbitrary code via a crafted packet in a TCP session on a wireless network.
ModificadaMedia (4.9)0.95%💥 ExploitBlackberry QNX Neutrino Rtos18/3/201417/6/2026
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.
ModificadaAlta (7.2)2.9%💥 ExploitBlackberry QNX Neutrino Rtos18/3/201417/6/2026
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.
ModificadaMedia (4.3)1.8%—Blackboard Vista/ce22/2/201417/6/2026
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.3%—Blackberry Enterprise ServiceBlackberry Universal Device ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express14/2/201417/6/2026
BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise…
ModificadaMedia (6.8)1.4%💥 ExploitSeagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 22021/1/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3)…
ModificadaMedia (4.3)3.2%💥 ExploitSeagate Blackarmor NAS 220 FirmwareSeagate Blackarmor NAS 2209/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php.
ModificadaMedia (6.8)0.91%—Blackberry Link18/11/201316/6/2026
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.
ModificadaMedia (5.8)1.9%—Blackberry Link18/11/201317/6/2026
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependent attackers to bypass intended restrictions on remote…
ModificadaAlta (7.9)0.96%—Blackberry Enterprise Service11/10/201316/6/2026
The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.
ModificadaMedia (6.2)0.35%—Blackberry OSBlackberry Z1013/7/201316/6/2026
BlackBerry 10 OS before 10.0.10.648 on BlackBerry Z10 smartphones uses weak permissions for a BlackBerry Protect object, which allows physically proximate attackers to bypass intended access restrictions by leveraging a user's BlackBerry Protect password-reset request and a user's installation of a crafted application.
ModificadaMedia (5.4)6.7%—Blackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos12/7/201316/6/2026
Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon…
ModificadaAlta (7.8)8.2%—Blackberry QNX Momentics Tool SuiteBlackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos12/7/201316/6/2026
Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via…
ModificadaAlta (10)4.4%—Seagate Blackarmor NAS25/5/201216/6/2026
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.
ModificadaAlta (7.9)6.5%—SambaRIM Blackberry Playbook TabletRIM Blackberry Playbook OS23/2/201216/6/2026
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers…
ModificadaMedia (5.8)0.96%—Ming Blacklist Free25/1/201216/6/2026
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack."
ModificadaAlta (7.2)0.36%—Blackberry Tablet OS8/12/201116/6/2026
The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive.
ModificadaMedia (6.5)2.1%—RIM Blackberry Enterprise Server21/10/201116/6/2026
The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact…
ModificadaMedia (4.3)3.5%💥 ExploitUlyssesonline Black-letterhead28/9/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
ModificadaMedia (6.4)2.2%—RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express14/7/201116/6/2026
Unspecified vulnerability in the BlackBerry Administration API in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 5.0.1 through 5.0.3, and BlackBerry Enterprise Server Express software 5.0.1 through 5.0.3, allows remote attackers to read text files or cause a denial of service via unknown vectors.
ModificadaMedia (4.3)1.9%—RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express18/4/201116/6/2026
Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server Express software 5.0.1 and 5.0.2, allows remote attackers to inject…
Orbitaley — Vulnerabilidades